On 14 July 2026, Microsoft shipped the largest Patch Tuesday in the company’s history: 622 CVEs in a single release, eclipsing every prior monthly bundle by a wide margin. Volume alone would make it notable, but it is not the number that should command the attention of every UK business running Microsoft 365. Buried inside that record haul are three zero-day vulnerabilities — two of them confirmed as being actively exploited in the wild before the patches existed — targeting on-premises SharePoint Server and Active Directory Federation Services (AD FS). The US Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency alert the same day, urging organisations to patch SharePoint immediately and to rotate their IIS machine keys. For UK SMEs running a hybrid deployment — on-premises SharePoint federated into Microsoft 365 through AD FS — this is the most operationally significant Patch Tuesday since the Hafnium campaign tore through Exchange Server in 2021.
The severity is not theoretical. The headline flaw, CVE-2026-58644, is a SharePoint remote code execution vulnerability carrying a CVSS score of 9.8, exploitable by an unauthenticated attacker through an insecure deserialization path — no login, no credential, no user interaction required. Alongside it, CVE-2026-56164 (a SharePoint elevation-of-privilege flaw) and CVE-2026-56155 (an AD FS privilege-escalation flaw that hands an attacker administrator rights) were both being used against real targets before Microsoft published a fix. Chained together, these vulnerabilities let an attacker compromise a SharePoint environment and then pivot into the wider Microsoft 365 tenant. This briefing sets out exactly what was released, why the SharePoint and AD FS cluster matters far more than the 622 headline, and why hybrid Microsoft 365 estates are the single most exposed configuration in the UK SME market this week.
What Microsoft actually released on 14 July 2026
Microsoft’s monthly security update — universally known as Patch Tuesday — lands on the second Tuesday of each month and is the primary vehicle through which the company ships fixes for its entire supported product range. The July 2026 edition is extraordinary for its scale: 622 CVEs addressed in one go, of which 56 are rated critical and 510 rated important, with the remainder spread across lower severity ratings. To put that in perspective, a typical Patch Tuesday resolves somewhere between 60 and 130 CVEs; the June 2026 release addressed 206, which itself felt large at the time. July 2026 is a step-change in volume that reflects both the growing complexity of Microsoft’s estate and the accelerating pace at which vulnerabilities are being discovered and disclosed.
But raw volume is a distraction. The overwhelming majority of those 622 CVEs are routine fixes that a disciplined patch cadence will absorb over the following days and weeks. What elevates this release from “large” to “emergency” is a tight cluster of vulnerabilities in on-premises SharePoint Server and Active Directory Federation Services. Three of these are zero-days — flaws that were either already being exploited in the wild or publicly known before Microsoft had a patch ready. Two of the three, CVE-2026-56164 and CVE-2026-56155, were confirmed under active exploitation. The third and most severe, CVE-2026-58644, was confirmed exploited on 15 July 2026, the day after release.
The affected products are specific and important to name: SharePoint Server Subscription Edition, SharePoint Server 2019 and SharePoint Server 2016. These are the on-premises versions that many UK organisations still run — either as a legacy document-management platform, an intranet, or as part of a hybrid architecture that federates on-premises identity and content into a cloud Microsoft 365 tenant. SharePoint Online, the fully cloud-hosted service, is not the target here; it is the on-premises server products, and the AD FS component that so often sits alongside them, that are in the firing line. That distinction is the whole story for UK SMEs.
The danger in the July release is not that three separate vulnerabilities happen to have shipped together — it is that they compose into a single attack path. CVE-2026-58644 (CVSS 9.8) allows an unauthenticated attacker to run arbitrary code on a SharePoint server through an insecure deserialization flaw, giving them an initial foothold with no credentials at all. CVE-2026-56164 is a SharePoint elevation-of-privilege flaw, remotely exploitable without authentication, that lets an attacker raise their level of access on that same server. And CVE-2026-56155 is an AD FS privilege-escalation flaw that lets a low-privilege foothold become a full administrator — the identity federation layer that bridges on-premises Active Directory and the Microsoft 365 cloud. Compromise SharePoint, escalate locally, then pivot through AD FS, and an attacker is no longer inside a document server — they are inside the trust relationship that governs your entire Microsoft 365 tenant. A separate SharePoint authentication-bypass flaw, CVE-2026-55040 (CVSS 9.1), can be chained to achieve unauthenticated RCE in its own right, and the patch for its chain component is not scheduled until August 2026 — meaning part of this exposure remains open even after you apply the July updates.
How the SharePoint and AD FS zero-day story unfolded
The July 2026 SharePoint cluster did not emerge from nowhere. It is the latest and most severe chapter in a run of on-premises SharePoint exploitation that has intensified across 2026. The timeline below sets out the chronology that frames the record release and the CISA emergency alert that accompanied it.
The vulnerabilities that matter most in this release
With 622 CVEs on the table, the practical question for any UK SME is prioritisation — which handful of flaws demand action this week rather than this month. The chart below ranks the most consequential vulnerabilities in the July 2026 bundle by relative urgency for a hybrid Microsoft 365 estate, combining CVSS severity, confirmed exploitation status and the ease of the attack. The percentages are an indicative urgency weighting to show relative priority, not the CVSS scores themselves.
The ranking makes the point that severity and exploitation status are not the same thing. CVE-2026-57092, a VMSwitch flaw carrying a fearsome CVSS of 9.9 that could allow a Hyper-V guest to escape to the host, and CVE-2026-56188, a Windows Server network-driver vulnerability at CVSS 9.8, are both extremely serious and warrant prompt patching — but neither is confirmed under active exploitation. The SharePoint and AD FS cluster sits at the top not only because the CVSS scores are high, but because attackers are demonstrably using these flaws right now, against real targets, with public proof-of-concept activity. For a resource-constrained SME, that distinction is how you decide what to do tonight versus what to schedule for the weekend. Exploited-in-the-wild, unauthenticated, internet-reachable flaws come first, every time.
Why the hybrid Microsoft 365 estate is the exposed configuration
The reason this release should worry UK SMEs specifically comes down to how many of them run a hybrid Microsoft 365 architecture without fully realising the risk it concentrates. In a hybrid deployment, an organisation keeps on-premises SharePoint Server and uses AD FS to federate identity into the Microsoft 365 cloud, so that a single set of credentials works across both. It is a common and historically sensible arrangement — but it means the on-premises SharePoint and AD FS servers are not isolated appliances. They are load-bearing components of the trust relationship that governs the entire cloud tenant.
Think through the attack path. An attacker finds an internet-facing on-premises SharePoint server — there is no shortage of them, and they are trivially discoverable through internet-wide scanning. Using CVE-2026-58644, they execute code on that server without any credential. Using CVE-2026-56164, they elevate their privileges locally. Then, because AD FS sits in the same trust boundary, they use CVE-2026-56155 to become an administrator of the federation service itself. At that point they can forge authentication tokens, impersonate any user in the tenant, and move laterally into email, SharePoint Online, OneDrive and Teams — the full Microsoft 365 environment — without ever needing a legitimate password. The on-premises server that looked like a legacy document store becomes the master key to the cloud. This is precisely the mechanism that made the 2021 Hafnium campaign against on-premises Exchange so damaging, and it is why the comparison is apt rather than hyperbolic.
Where hybrid UK SMEs are most exposed
The July release is, in effect, a stress test of how well a UK SME manages its on-premises Microsoft footprint and the identity plumbing that connects it to the cloud. Most fail that test in a predictable set of places. The grid below maps where the exposure concentrates for a typical hybrid mid-market organisation.
The pattern is consistent: the businesses most at risk are those running ageing on-premises SharePoint and AD FS infrastructure without a disciplined patch cadence, without an inventory of what is internet-reachable, and without the monitoring to detect a compromise after the fact. The last point matters because CVE-2026-58644 and its siblings are deserialization and authentication flaws — an attacker who exploits one can plant a web shell that survives the patch. Applying the July update closes the door, but it does not evict anyone already inside. That is exactly why CISA’s alert paired “patch immediately” with “rotate IIS machine keys” and hunt for signs of compromise: the machine-key rotation invalidates forged authentication material an attacker may already have stolen, and threat-hunting finds the foothold the patch alone leaves in place.
What remediation and resilience cost by business size
Closing this exposure is not a single purchase; it is a combination of urgent patching, hardening, threat-hunting and, for many organisations, a strategic decision about whether to keep running on-premises SharePoint at all. The table below sets out indicative planning ranges for the combined remediation and resilience work across UK business-size bands. Figures are illustrative planning ranges, not fixed quotes, and assume a hybrid Microsoft 365 estate.
| Business size | Typical Microsoft estate in scope | Remediation & resilience path | Indicative investment |
|---|---|---|---|
| 1–10 staff | Microsoft 365 cloud only, or a single legacy SharePoint box | Emergency patch, machine-key rotation, or retire the on-prem server and go cloud-only | £500–£3,000 |
| 10–50 staff | On-premises SharePoint 2016/2019 federated via AD FS into M365 | Patch, harden, rotate keys, threat-hunt, plan migration to SharePoint Online | £3,000–£12,000 |
| 50–200 staff | Multiple SharePoint farms, AD FS, servers, several SaaS integrations | Coordinated emergency remediation, compromise assessment, phased cloud migration | £12,000–£35,000 |
| 200+ staff | Complex hybrid estate, regulated data, contractual security obligations | Incident-grade response, continuous monitoring, managed migration programme | £35,000+ |
The right figure for any given business depends on the starting state of the estate and, crucially, on the strategic decision behind the remediation. An organisation that patches promptly and has already been reducing its on-premises footprint will spend far less than one discovering an un-inventoried SharePoint farm mid-incident. But the more important number is the one not in the table: the cost of a full Microsoft 365 tenant compromise. Once an attacker owns AD FS, they own identity, and identity compromise is the most expensive category of incident an SME can suffer — combining data theft, business email compromise, extortion and the regulatory exposure that follows under UK GDPR. Against that, an emergency patch-and-harden exercise and a considered migration off legacy on-premises SharePoint is a modest and rational investment.
Reactive scramble versus a governed Microsoft 365 posture
This release exposes the gap between treating Microsoft 365 as a set-and-forget cloud service and treating the whole estate — cloud and the on-premises identity plumbing behind it — as a governed, monitored, actively maintained system. The comparison below sets out the two postures.
Reactive posture
How most hybrid SMEs run today
- On-premises SharePoint and AD FS patched only when something breaks
- No inventory of which Microsoft servers face the internet
- Critical vulnerabilities left open for weeks after disclosure
- IIS machine keys never rotated, even after a scare
- No monitoring for web shells or forged authentication tokens
- Legacy on-premises SharePoint kept indefinitely with no exit plan
- Microsoft 365 treated as a bill, not a governed environment
Governed posture
Where Cloudswitched takes you
- Emergency patches applied within hours for exploited zero-days
- Every internet-facing Microsoft server inventoried and owned
- A defined patch cadence with documented compliance evidence
- Machine-key rotation and hardening built into the response
- Monitoring and threat-hunting to catch post-exploitation footholds
- A managed migration path off legacy on-premises SharePoint
- Microsoft 365 configured, secured and monitored end to end
Moving from the left column to the right is a shift from firefighting to governance. The July 2026 release rewards organisations that had already reduced their on-premises attack surface and punishes those that let legacy infrastructure drift. For many UK SMEs, the honest conclusion this episode forces is that the safest long-term answer is to stop running internet-facing on-premises SharePoint altogether — migrating content into the fully managed, continuously patched Microsoft 365 cloud, where the deserialization and federation flaws that define this incident simply do not present the same exposure. A managed migration removes the class of risk rather than merely patching this instance of it.
You do not need to decide your whole cloud strategy tonight to act on this. The single most valuable exercise a UK SME can run this week is a Microsoft exposure review: identify every on-premises SharePoint Server (Subscription Edition, 2019 or 2016) and every AD FS server in your estate, record the exact build number and the date each was last patched, and confirm which of them are reachable from the public internet. For any internet-facing SharePoint or AD FS server, apply the July 2026 updates immediately, rotate the IIS machine keys as CISA advises, and check the server for unexpected files or web shells that may indicate a foothold that pre-dates the patch. If you cannot confirm a server was patched before 15 July 2026, treat it as potentially compromised and hunt accordingly. Most businesses cannot answer these questions today, and discovering that is the point: it converts an invisible, internet-reachable exposure into a managed one, and it is the natural first step toward deciding whether that server should exist at all.
At-a-glance: the July 2026 Patch Tuesday
| Fact | Detail |
|---|---|
| Release date | 14 July 2026 — the largest Patch Tuesday in Microsoft’s history |
| Total CVEs | 622, comprising 56 critical and 510 important |
| Zero-days | 3 — two actively exploited, one publicly known before the patch |
| CVE-2026-58644 | SharePoint RCE, CVSS 9.8, unauthenticated deserialization, exploited 15 July |
| CVE-2026-56164 | SharePoint elevation of privilege, actively exploited, unauthenticated, remote |
| CVE-2026-56155 | AD FS privilege escalation, actively exploited, gains administrator rights |
| CVE-2026-55040 | SharePoint authentication bypass, CVSS 9.1, chainable to unauthenticated RCE |
| CVE-2026-32201, CVE-2026-45659 | Additional SharePoint chain flaws, added to the CISA KEV catalogue |
| CVE-2026-57092 | VMSwitch, CVSS 9.9 — Hyper-V guest-to-host escape |
| CVE-2026-56188 | Windows Server network driver, CVSS 9.8 |
| CISA action | Emergency alert on 14 July: patch and harden SharePoint, rotate IIS machine keys |
| Affected products | SharePoint Server Subscription Edition, 2019 and 2016; AD FS |
| Outstanding fix | Chain component for the CVE-2026-55040 path scheduled for August 2026 |
| Highest-risk configuration | Hybrid Microsoft 365: on-premises SharePoint federated via AD FS |
| Historical comparison | Most significant since the 2021 Hafnium campaign against on-premises Exchange |
How this connects to the wider 2026 threat picture
The July 2026 Patch Tuesday does not stand alone. It is the latest thread in a year of developments all pointing the same way: attackers are moving faster than ever from disclosure to mass exploitation, the weakest link is the unpatched internet-facing server, and the organisations that suffer are those without a governed patch programme and a plan to retire legacy infrastructure. The SharePoint and AD FS cluster is the operational face of a broader shift toward automated, near-instant weaponisation of high-severity flaws.
The perimeter-device and rapid-exploitation dimension runs directly through our coverage of the AI-driven CVE surge and why a real patch programme now matters, which quantifies exactly why a 622-CVE month is becoming the new normal. The device-centric, indiscriminate targeting model that makes an unpatched server so dangerous is set out in our analysis of the Check Point June 2026 report and The Gentlemen ransomware operation, and the perimeter-firewall version of the same problem in our reporting on the FortiBleed campaign and 73,932 compromised Fortinet firewalls. The connectivity and network-edge exposure that so often sits alongside these Microsoft servers is examined in our coverage of the NCSC and FSB router advisory for UK SMEs. And the cloud-concentration and regulatory backdrop — why so much now depends on how well a handful of hyperscale providers are governed — is explored in our look at the UK critical third party designation for Microsoft, Google, AWS and Oracle. Together these establish the message the July release makes concrete: in a landscape of near-instant exploitation, a governed patch cadence and a plan to reduce your on-premises attack surface are the whole game.
Your on-premises SharePoint could be the master key to your Microsoft 365 tenant
The July 2026 zero-days turn a legacy document server into a route straight into your cloud environment. Cloudswitched delivers managed Microsoft 365 migration and support — retiring exposed on-premises SharePoint, hardening what must stay, and moving your content into the continuously patched cloud with SPF, DKIM, DMARC and MFA enforced — so this class of risk is removed, not just patched this month.
Talk to us about Cloud Email & Microsoft 365Frequently asked questions
Patch the emergency now — then remove the risk for good
The July 2026 zero-days are a reminder that internet-facing on-premises SharePoint is a strategic liability, not just this month’s patch. Cloudswitched delivers managed Microsoft 365 migration and support — emergency remediation and machine-key rotation today, then a planned move off legacy on-premises infrastructure into the continuously patched cloud — so your business is out of this attack’s path, with the evidence to prove it to customers and auditors alike.
Talk to us about Cloud Email & Microsoft 365


